
EVENSTAR
Intel 64/Windows low-level experiments

Intel 64/Windows low-level experiments

Windows command-line utility for reading, writing, and executing kernel-mode code from Administrator context using a font validation execution…

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"

Using CVE-2023-21768 to manual map kernel mode driver

Proof of concept & details for CVE-2025-21298

BOF to run PE in Cobalt Strike Beacon without console creation

针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Visualize the virtual address space of a Windows process on a Hilbert curve.

A Windows kernel dump C++ parser library with Python 3 bindings.

CVE-2025-31200 - @Noahhw46 figured it out

POC for CVE-2018-0824

Spectre exploit

Integer overflow in FreeType software, which also affects Chrome

Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

xnu kernel heap info leak